1. Current approach
Summa uses only cookies or browser storage necessary to provide, secure and remember the service, with one optional exception: the X (Twitter) advertising pixel described in section 4, which runs only if you accept it.
Legal · Version 1.3 · Effective 30 September 2026
Summa uses only technologies necessary to provide, secure and remember the service, plus one optional advertising pixel from X that runs only with your consent.
Summa uses only cookies or browser storage necessary to provide, secure and remember the service, with one optional exception: the X (Twitter) advertising pixel described in section 4, which runs only if you accept it.
| Name | Type | Purpose | Duration |
|---|---|---|---|
| authjs.session-token | Cookie | Keeps you signed in and protects the session | 12 hours |
| authjs.csrf-token | Cookie | Prevents request forgery | Session |
| authjs.callback-url, authjs.state, authjs.pkce.code_verifier | Cookies | Complete a secure sign-in exchange | Short-lived |
| auth_flow | Cookie | Carries sign-in, two-factor and password-reset steps | Short-lived |
| active_tenant_id | Cookie | Remembers which workspace you selected | 30 days |
| NEXT_LOCALE | Cookie and local storage | Remembers your chosen language | 1 year |
| sidebar_state | Cookie | Remembers whether the chat history panel is open | 7 days |
| summa-chat-tabs:<account> | Local storage | Remembers which chats you keep open as tabs, per account on this device | Until cleared |
| react-resizable-panels:summa-chat-layout… | Local storage | Remembers how wide you made the panel beside a chat | Until cleared |
| summa-theme | Local storage | Remembers light or dark appearance | Until cleared |
| summa_tracking_consent | Cookie | Remembers whether you accepted or rejected the optional X pixel | 6 months |
Language, the chat layout and tabs, appearance and your answer about the X pixel each remember a choice you made yourself. None of these technologies is used for advertising, profiling or cross-site tracking, and none is shared with a third party.
We measure how the public website is used so we can see which pages are useful and whether the site performs well. This measurement uses no cookies and stores nothing on your device, which is why you are not asked for consent for it: the rules on consent govern access to your device, and we do not access it.
Instead, when you open a page our own servers record that page, the response status, the referring website's domain name, and a coarse description of your device, browser and operating system. Your IP address is used only to derive a short-lived visitor code and is never stored. That code is produced with a secret key which is replaced and destroyed every day, so visits cannot be linked from one day to the next — by us or by anyone else. There is no profile, no advertising use, and no third party involved.
Once a page has loaded, moving to another page of the site usually happens without a new page request our servers could tell apart from the browser preparing a link in advance. So our own page code tells our servers which page you moved to, and it is recorded in the same way, under the same daily visitor code. Pages the browser only prepares in advance, without you opening them, are not recorded. This too stores nothing on your device.
On the public pages, our own page code also reports which links and buttons you click: the page you were on, the fixed name we gave the button, and where a link leads — a page on our site, or only the domain name of another site. It is sent to our servers under the same daily visitor code and nothing else. It never records what you type, the text on the screen, mouse movements or scrolling, and it stores nothing on your device.
If the link you arrived by carries campaign labels — the utm_… tags an advertiser adds to an ad or newsletter link — we record those labels. If it carries an advertising platform’s own click identifier instead, we record only which platform it came from, never the identifier. If an account is created during that visit, we record that an account was created, under the same daily visitor code and with nothing that identifies the account, so we can see which campaigns bring sign-ups. Every other part of a link’s address is discarded.
| What we record | Why | How long |
|---|---|---|
| Requested page and response status | See which pages are used and which are failing | Up to 90 days |
| Links and buttons you click, by their fixed name or destination | See which buttons and links on the site are used | Up to 90 days |
| Campaign labels of the link you arrived by | See which campaigns bring visitors | Up to 90 days |
| That an account was created in the same visit | See which campaigns bring sign-ups | Up to 90 days; never linked to the account |
| Referring website domain | Understand where visitors come from | Up to 90 days |
| Device, browser and operating system category | Ensure the site works on real devices | Up to 90 days |
| Daily visitor code derived from IP address | Count visitors and visits without identifying anyone | Up to 90 days; the key is destroyed daily |
| Page performance measurements | Detect slow pages for real visitors | Up to 90 days |
After 90 days the detailed records are deleted and only daily totals remain. Because no stored value can be linked back to a person once the daily key is destroyed, these statistics cannot be tied to an individual and therefore fall outside data subject access and erasure requests. Our lawful basis for this limited processing is legitimate interest.
Pages inside your account — the chat, settings and administration areas — are excluded from website statistics entirely, clicks included.
We advertise on X and want to know whether those ads lead to sign-ups. For that we offer one optional technology, the X pixel, provided by Twitter International Unlimited Company (Ireland) and X Corp. (United States). It stays switched off until you press Accept in the banner; rejecting is just as easy and changes nothing about how summa works for you.
| What | Purpose | Duration |
|---|---|---|
| X pixel script, loaded from static.ads-twitter.com | Reports visits to our public pages to X, so a sign-up can be attributed to an ad | Only while you consent |
| _twclid | First-party cookie holding the identifier of the X ad you clicked | As set by X |
| Cookies on X's own domains | Set and read by X under its own privacy policy | As set by X |
| Signup event | Tells X that an account was created, identified only by a random account number — never your name, email address or conversations | Sent once per account |
Inside your account the pixel does not report page views; the only thing measured there is the signup event. You can change your answer at any time through Cookie settings in the website footer. Withdrawing removes the _twclid cookie and reloads the page without the pixel. We do not use session recording, heatmaps or any other advertising technology.
Apart from the X pixel, and only after you accept it, the website loads no third-party scripts, fonts, or content delivery networks. Typefaces are served from our own servers, so until then loading a page sends no request to any outside provider and no outside provider receives your IP address.
Blocking necessary cookies may prevent login or other essential functionality.